1
0
mirror of https://github.com/rbmm/SC synced 2026-06-08 17:03:41 +00:00
Files
rbmm 1f8322ef08 *
2025-05-16 15:02:40 +03:00

158 lines
11 KiB
Plaintext

ScLfm
Timestamp is 6827280b (Fri May 16 14:56:59 2025)
Preferred load address is 00400000
Start Length Name Class
0001:00000000 0000050aH .text$mn CODE
0001:0000050a 00000abeH .text$mn$cpp CODE
0001:00000fc8 00000018H .text$mn$cpp$r CODE
0001:00000fe0 00001020H .text$mn$cpp$s CODE
0001:00002000 00000320H .text$mn$cpp$u CODE
0001:00002320 00000000H .text$mn$cpp$v CODE
0001:00002320 00000006H .text$nm CODE
0001:00002326 000000cbH .text$zz CODE
0002:00000000 000000b0H .rdata DATA
0002:000000b0 00000000H .edata DATA
0002:000000b0 00000064H .rdata$zzzdbg DATA
0003:00000000 00000000H .data DATA
0003:00000000 00000008H .bss DATA
Address Publics by Value Rva+Base Lib:Object
0000:00000000 ___AbsoluteZero 00000000 <absolute>
0000:00000000 ___arm64x_extra_rfe_table 00000000 <absolute>
0000:00000000 ___arm64x_extra_rfe_table_size 00000000 <absolute>
0000:00000000 ___arm64x_native_entrypoint 00000000 <absolute>
0000:00000000 ___arm64x_redirection_metadata 00000000 <absolute>
0000:00000000 ___arm64x_redirection_metadata_count 00000000 <absolute>
0000:00000000 ___dynamic_value_reloc_table 00000000 <absolute>
0000:00000000 ___enclave_config 00000000 <absolute>
0000:00000000 ___guard_check_icall_a64n_fptr 00000000 <absolute>
0000:00000000 ___guard_eh_cont_count 00000000 <absolute>
0000:00000000 ___guard_eh_cont_table 00000000 <absolute>
0000:00000000 ___guard_fids_count 00000000 <absolute>
0000:00000000 ___guard_fids_table 00000000 <absolute>
0000:00000000 ___guard_flags 00000000 <absolute>
0000:00000000 ___guard_iat_count 00000000 <absolute>
0000:00000000 ___guard_iat_table 00000000 <absolute>
0000:00000000 ___guard_longjmp_count 00000000 <absolute>
0000:00000000 ___guard_longjmp_table 00000000 <absolute>
0000:00000000 ___hybrid_auxiliary_delayload_iat 00000000 <absolute>
0000:00000000 ___hybrid_auxiliary_delayload_iat_copy 00000000 <absolute>
0000:00000000 ___hybrid_auxiliary_iat 00000000 <absolute>
0000:00000000 ___hybrid_auxiliary_iat_copy 00000000 <absolute>
0000:00000000 ___hybrid_code_map 00000000 <absolute>
0000:00000000 ___hybrid_code_map_count 00000000 <absolute>
0000:00000000 ___hybrid_image_info_bitfield 00000000 <absolute>
0000:00000000 ___volatile_metadata 00000000 <absolute>
0000:00000000 ___x64_code_ranges_to_entry_points 00000000 <absolute>
0000:00000000 ___x64_code_ranges_to_entry_points_count 00000000 <absolute>
0000:00000000 ___ImageBase 00400000 <linker-defined>
0001:00000000 ?epASM@@YGXXZ 00401000 f x86.obj
0001:00000037 ?__Address@@YIPAXPBX@Z 00401037 f x86.obj
0001:0000004a __alloca_probe 0040104a f x86.obj
0001:0000004a __chkstk 0040104a f x86.obj
0001:000000e2 ?aretFromMapViewOfSection@@YGJXZ 004010e2 f x86.obj
0001:000000e9 _ZwMapViewOfSection@40 004010e9 f x86.obj
0001:0000010a _ZwUnmapViewOfSection@8 0040110a f x86.obj
0001:0000012b _RtlDosPathNameToNtPathName_U_WithStatus@16 0040112b f x86.obj
0001:0000014c _NtOpenFile@24 0040114c f x86.obj
0001:0000016d _RtlFreeUnicodeString@4 0040116d f x86.obj
0001:0000018e _RtlGetCurrentPeb@0 0040118e f x86.obj
0001:000001af _RtlAllocateHeap@12 004011af f x86.obj
0001:000001d0 _RtlInitUnicodeString@8 004011d0 f x86.obj
0001:000001f1 _NtQueryDirectoryFile@44 004011f1 f x86.obj
0001:00000212 _LdrGetDllHandle@16 00401212 f x86.obj
0001:00000233 _NtCreateSection@28 00401233 f x86.obj
0001:00000254 _NtClose@4 00401254 f x86.obj
0001:00000275 _RtlAppendUnicodeStringToString@8 00401275 f x86.obj
0001:00000296 _RtlFreeHeap@12 00401296 f x86.obj
0001:000002b7 _RtlPushFrame@4 004012b7 f x86.obj
0001:000002d8 _RtlPopFrame@4 004012d8 f x86.obj
0001:000002f9 _RtlGetFrame@0 004012f9 f x86.obj
0001:0000031a _ZwProtectVirtualMemory@20 0040131a f x86.obj
0001:0000033b _RtlEqualUnicodeString@12 0040133b f x86.obj
0001:0000035c _RtlAddVectoredExceptionHandler@8 0040135c f x86.obj
0001:0000037d _ZwSetContextThread@8 0040137d f x86.obj
0001:0000039e _LdrLoadDll@16 0040139e f x86.obj
0001:000003bf _LdrUnloadDll@4 004013bf f x86.obj
0001:000003e0 _RtlRemoveVectoredExceptionHandler@4 004013e0 f x86.obj
0001:00000401 _LdrAddRefDll@8 00401401 f x86.obj
0001:00000422 _RtlImageNtHeaderEx@20 00401422 f x86.obj
0001:00000443 _LdrEnumerateLoadedModules@12 00401443 f x86.obj
0001:00000464 _RtlWow64EnableFsRedirection@4 00401464 f x86.obj
0001:00000485 _RtlAppendUnicodeToString@8 00401485 f x86.obj
0001:000004a6 _memcpy 004014a6 f x86.obj
0001:000004c7 _LdrGetProcedureAddress@16 004014c7 f x86.obj
0001:000004e8 _memset 004014e8 f x86.obj
0001:0000050a ?IsImageOk@@YGEKPAX@Z 0040150a f ep.obj
0001:00000618 ?FindNoCfgDll@@YGJKPAU_UNICODE_STRING@@@Z 00401618 f ep.obj
0001:0000080a ?get@IMAGE_Ctx@@SGPAU1@XZ 0040180a f i ep.obj
0001:0000085e ?OverwriteSection@@YGJPAX0PAU_IMAGE_NT_HEADERS@@@Z 0040185e f ep.obj
0001:000009f0 ?retFromMapViewOfSection@@YIJJ@Z 004019f0 f ep.obj
0001:00000a4c ?MyVexHandler@@YGJPAU_EXCEPTION_POINTERS@@@Z 00401a4c f ep.obj
0001:00000af0 ?LoadLibraryFromMem@@YGJPAPAXPAXPAU_IMAGE_NT_HEADERS@@PBU_UNICODE_STRING@@@Z 00401af0 f ep.obj
0001:00000ca6 ?CheckModule@@YGXPAU_LDR_DATA_TABLE_ENTRY@@PAUDSC@@PAE@Z 00401ca6 f ep.obj
0001:00000cd8 ?LoadLibraryFromMem@@YGJPAXKPAPAX@Z 00401cd8 f ep.obj
0001:00000dd5 ?GetNtBase@@YGPAXXZ 00401dd5 f ScEntry:GetFuncAddr.obj
0001:00000de8 ?get_hmod@@YIPAXPB_W@Z 00401de8 f ScEntry:GetFuncAddr.obj
0001:00000e32 ?GetFuncAddressEx@@YIPAXPAU_IMAGE_DOS_HEADER@@PBD@Z 00401e32 f ScEntry:GetFuncAddr.obj
0001:00000fc8 __GUID_1fc98bca_1ba9_4397_93f9_349ead41e057 00401fc8 ep.obj
0001:00000fe0 ??_C@_1M@HNNPBALB@?$AA?$CK?$AA?4?$AAd?$AAl?$AAl@FNODOBFM@ 00401fe0 ep.obj
0001:00000ff0 ??_C@_0BD@PPCCBCGB@ZwMapViewOfSection@FNODOBFM@ 00401ff0 ep.obj
0001:00001010 ??_C@_0BG@EDOIKHNH@RtlSetProtectedPolicy@FNODOBFM@ 00402010 ep.obj
0001:00001030 ??_C@_1BG@NCCDOFIB@?$AA?2?$AAs?$AAy?$AAs?$AAt?$AAe?$AAm?$AA3?$AA2?$AA?2@FNODOBFM@ 00402030 ep.obj
0001:00002320 ?sc_end@@YGPAXXZ 00403320 f ScEntry:prepare.obj
0001:00002326 ?ScEntry@@YGXPAU_PEB@@@Z 00403326 f ScEntry:prepare.obj
0002:00000000 ??_C@_0BF@EKFKPNAI@RtlInitUnicodeString@ 00404000 ScEntry:prepare.obj
0002:00000018 ??_C@_1BI@NEOFKCPM@?$AAp?$AAr?$AAe?$AAp?$AAa?$AAr?$AAe?$AA?4?$AAd?$AAl?$AAl@ 00404018 ScEntry:prepare.obj
0002:00000030 ??_C@_0L@HOFGLFDL@LdrLoadDll@ 00404030 ScEntry:prepare.obj
0002:0000003c ??_C@_0BH@GKPJJDBO@LdrGetProcedureAddress@ 0040403c ScEntry:prepare.obj
0002:00000054 ??_C@_0N@FIGJGHFN@LdrUnloadDll@ 00404054 ScEntry:prepare.obj
0002:00000064 ??_C@_0BD@JDDPIELM@RtlExitUserProcess@ 00404064 ScEntry:prepare.obj
0003:00000000 ___@@_PchSym_@00@UfhvihUsziibUwlxfnvmghUtrgsfyUhxUgnkUdrmDCUivovzhvUhxounUhgwzucOlyq@4B2008FD98C1DD4 00405000 stdafx.obj
0003:00000004 ___@@_PchSym_@00@UfhvihUsziibUwlxfnvmghUtrgsfyUhxUgnkUdrmDCUivovzhvUhxvmgibUhgwzucOlyq@4B2008FD98C1DD4 00405004 ScEntry:stdafx.obj
entry point at 0001:00002326
Static symbols
0001:0000000a common_imp_call 0040100a f x86.obj
0001:00000075 protect 00401075 f x86.obj
0001:00002000 ?_ZwMapViewOfSection@40 00403000 x86.obj
0001:00002000 @imp_begin@ 00403000 x86.obj
0001:00002018 ?_ZwUnmapViewOfSection@8 00403018 x86.obj
0001:00002034 ?_RtlDosPathNameToNtPathName_U_WithStatus@16 00403034 x86.obj
0001:00002060 ?_NtOpenFile@24 00403060 x86.obj
0001:00002070 ?_RtlFreeUnicodeString@4 00403070 x86.obj
0001:0000208c ?_RtlGetCurrentPeb@0 0040308c x86.obj
0001:000020a4 ?_RtlAllocateHeap@12 004030a4 x86.obj
0001:000020b8 ?_RtlInitUnicodeString@8 004030b8 x86.obj
0001:000020d4 ?_NtQueryDirectoryFile@44 004030d4 x86.obj
0001:000020f0 ?_LdrGetDllHandle@16 004030f0 x86.obj
0001:00002104 ?_NtCreateSection@28 00403104 x86.obj
0001:00002118 ?_NtClose@4 00403118 x86.obj
0001:00002124 ?_RtlAppendUnicodeStringToString@8 00403124 x86.obj
0001:00002148 ?_RtlFreeHeap@12 00403148 x86.obj
0001:00002158 ?_RtlPushFrame@4 00403158 x86.obj
0001:0000216c ?_RtlPopFrame@4 0040316c x86.obj
0001:0000217c ?_RtlGetFrame@0 0040317c x86.obj
0001:0000218c ?_ZwProtectVirtualMemory@20 0040318c x86.obj
0001:000021a8 ?_RtlEqualUnicodeString@12 004031a8 x86.obj
0001:000021c4 ?_RtlAddVectoredExceptionHandler@8 004031c4 x86.obj
0001:000021e8 ?_ZwSetContextThread@8 004031e8 x86.obj
0001:00002200 ?_LdrLoadDll@16 00403200 x86.obj
0001:00002210 ?_LdrUnloadDll@4 00403210 x86.obj
0001:00002224 ?_RtlRemoveVectoredExceptionHandler@4 00403224 x86.obj
0001:0000224c ?_LdrAddRefDll@8 0040324c x86.obj
0001:00002260 ?_RtlImageNtHeaderEx@20 00403260 x86.obj
0001:00002278 ?_LdrEnumerateLoadedModules@12 00403278 x86.obj
0001:00002298 ?_RtlWow64EnableFsRedirection@4 00403298 x86.obj
0001:000022b8 ?_RtlAppendUnicodeToString@8 004032b8 x86.obj
0001:000022d8 ?_memcpy 004032d8 x86.obj
0001:000022e4 ?_LdrGetProcedureAddress@16 004032e4 x86.obj
0001:00002300 ?_memset 00403300 x86.obj
0001:0000230c @ntdllp 0040330c x86.obj